Certificate Expiry Monitoring

Solace Insights Monitors for Datadog Reference provides information to help you understand how to read and filter the information provided by the monitors offered by your Insights Datadog account.

These monitors track certificate expiration dates for various certificate types configured on your event brokers, including client certificate authorities, domain certificate authorities, Kafka certificates, OAuth profile certificates, and RDP REST consumer certificates.

Monitor Name Monitor Type Status Default Severity Configured Details

Client Certificate Authority - Expiry

Metric Active

Alert or Warning

A client certificate authority (CA) configured on this event broker is approaching its expiration date.

Predicted Impact: When this CA expires, the event broker no longer validates client certificates that were signed by this CA. Any clients using certificates signed by this CA will fail to authenticate, preventing them from connecting to the event broker.

Recommended Actions: Identify the affected CA using the alert details. Obtain a renewed CA certificate from your certificate issuer or internal PKI team and update it on the event broker before the expiry date. Verify that client authentication continues to work after renewal. Use the Certificate Expiry dashboard in Insights to track expiry status across your event brokers.

Contact Solace for assistance if required.

Domain Certificate Authority - Expiry

Metric Active

Alert or Warning

A domain certificate authority (CA) configured on this event broker is approaching its expiration date.

Predicted Impact: When this CA expires, the event broker will no longer be able to validate the TLS certificates presented by outbound connections that rely on it. Any bridges, Kafka senders or receivers, REST Delivery Points (RDPs), or LDAP connections that use this CA for server certificate validation will fail to establish or re-establish their connections after expiry.

Recommended Actions: Identify which bridges, Kafka connectors, REST Delivery Points, and LDAP connections are configured to use the expiring CA on this service. Obtain the renewed CA certificate from your certificate issuer or internal PKI team and update it on the event broker before the expiry date. Verify that all dependent connections are operational after renewal. Use the Certificate Expiry dashboard in Insights to track expiry status across your services.

Contact Solace for assistance if required.

Kafka Receiver Certificate - Expiry

Metric Active

Alert or Warning

A Kafka receiver client certificate configured on this event broker is approaching its expiration date.

Predicted Impact: When this certificate expires, the Kafka Receiver no longer authenticates with the Kafka cluster. Messages will stop being received from Kafka topics, disrupting data flow into your messaging infrastructure.

Recommended Actions: Identify the affected Kafka Receiver using the alert details. Obtain a renewed client certificate from your certificate issuer or internal PKI team and update it on the event broker before the expiry date. Verify that the Kafka Receiver connection is operational after renewal. Use the Certificate Expiry dashboard in Insights to track expiry status across your event brokers.

Contact Solace for assistance if required.

Kafka Sender Certificate - Expiry

Metric Active

Alert or Warning

A Kafka sender client certificate configured on this event broker is approaching its expiration date.

Predicted Impact: When this certificate expires, the Kafka sender no longer authenticates with the Kafka cluster. Messages will stop being sent to Kafka topics, disrupting data flow from your messaging infrastructure to Kafka.

Recommended Actions: Identify the affected Kafka sender using the alert details. Obtain a renewed client certificate from your certificate issuer or internal PKI team and update it on the event broker before the expiry date. Verify that the Kafka sender connection is operational after renewal. Use the Certificate Expiry dashboard in Insights to track expiry status across your event brokers.

Contact Solace for assistance if required.

OAuth Profile Certificate - Expiry

Metric Active

Alert or Warning

An OAuth profile client certificate configured on this event broker is approaching its expiration date.

Predicted Impact: When this certificate expires, the event broker no longer authenticates with the OAuth provider. OAuth-based authentication will fail, preventing clients that rely on OAuth tokens from connecting to the event broker.

Recommended Actions: Identify the affected OAuth profile using the alert details. Obtain a renewed client certificate from your certificate issuer or internal PKI team and update it on the event broker before the expiry date. Verify that OAuth authentication continues to work after renewal. Use the Certificate Expiry dashboard in Insights to track expiry status across your event brokers.

Contact Solace for assistance if required.

RDP REST Consumer Certificate - Expiry

Metric Active

Alert or Warning

A REST Delivery Point (RDP) REST consumer client certificate configured on this event broker is approaching its expiration date.

Predicted Impact: When this certificate expires, the RDP REST consumer no longer authenticates with the REST endpoint. Messages will stop being delivered to the REST consumer endpoint, disrupting data flow from your messaging infrastructure.

Recommended Actions: Identify the affected RDP REST consumer using the alert details. Obtain a renewed client certificate from your certificate issuer or internal PKI team and update it on the event broker before the expiry date. Verify that the REST Consumer connection is operational after renewal. Use the Certificate Expiry dashboard in Insights to track expiry status across your event brokers.

Contact Solace for assistance if required.